Loading HuntDB...

GHSA-6339-gv7w-g5f4

GitHub Security Advisory

SAP HANA Node.js client package vulnerable to Prototype Pollution

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to global object prototypes. This is due to improper user input sanitation when using the nestTables feature causing low impact on the availability of the application. This has no impact on Confidentiality and Integrity.

Affected Packages

npm @sap/hana-client
Affected versions: 2.0.0 (fixed in 2.21.31)

Related CVEs

Key Information

GHSA ID
GHSA-6339-gv7w-g5f4
Published
October 8, 2024 6:30 AM
Last Modified
October 8, 2024 2:37 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
@sap/hana-client
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.